News By Tag Industry News News By Location Country(s) Industry News
| Paladion Helps Joomla Developers Stop Cybersecurity RisksRapid Identification of Vulnerabilities in Joomla Patches Enables Speedy Corrections for Users
By: Paladion As part of its continual, intensive cybersecurity monitoring and research, Paladion found instances of data not being validated when being exported from Joomla extensions to a CSV file format. Paladion security expert Suresh Narvaneni, who found the flaws, said, "This vulnerability made it possible for an attacker to spread malware via spreadsheets such as Microsoft Excel and LibreOffice Calc. Unauthorized remote machine access was also possible."Suresh identified the issue in specific Joomla extensions from Acyba and notified Joomla immediately. In addition, a missing validation on a URL field when creating a new company record and a vulnerability to cross-site-scripting (XSS) were found in the JS Jobs extension from Joom Sky. Joomla then contacted the developers for the extensions concerned, with issues being fixed within one day. Joomla also published a note on the vulnerability at https://vel.joomla.org/ Using the information from Paladion, extension developer Acyba rapidly released a patchto protect exports of data destined for Excel. Extension developer Joom Sky also released a patch for JS Jobs. For the following Joomla extensions, Paladion recommends users take these actions: for AcySMS, update this extension to version 3.5.1 or later; for AcyMailing, update this extension to version 5.9.6 or later; for JS Jobs, update this extension to version 1.2.1. Paladion also said that security operations centers could identify such vulnerabilities in other extensions by checking for malicious user input such as macro injection or link injection (as for AcySMS, AcyMailing) or JavaScript injection (as for JS Jobs). End
|
| ||||||||||||||||||||||||||||||||||||||||||||||||